CVE-2017-7921, CVE-2021-22681, CVE-2021-30952, CVE-2021-33044, CVE-2021-36260, CVE-2023-41974, CVE-2023-43000, CVE-2023-6895, CVE-2024-53219, CVE-2025-34067, CVE-2025-68121, CVE-2026-20079, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20131, CVE-2026-21536, CVE-2026-23651, CVE-2026-24821, CVE-2026-26125, CVE-2026-27141, CVE-2026-3094
IP Addresses:
20.9.8.2, 20.12.5.3, 20.15.4.2, 20.18.2.1, 2.1.0.39
Get tomorrow's brief in your inbox
Today: CISA adds five actively exploited vulnerabilities to the KEV catalog with a March 26 remediation deadline. Cisco confirms two more SD-WAN flaws are under active exploitation, and discloses two CVSS 10.0 firewall bugs. Google reports 90 zero-days exploited in 2025, with enterprise tech taking 48% of hits and commercial spyware vendors overtaking state actors. Phobos ransomware leader pleads guilty to $39 million global extortion scheme.
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA added five vulnerabilities to the KEV catalog on March 5 based on evidence of active exploitation. The list includes CVE-2017-7921 (Hikvision improper authentication, CVSS 9.8, EPSS 94.1%), CVE-2021-22681 (Rockwell Automation insufficiently protected credentials, CVSS 9.8), and three Apple flaws: CVE-2023-41974 and CVE-2023-43000 (use-after-free in iOS/iPadOS), and CVE-2021-30952 (integer overflow). Federal agencies must remediate by March 26, 2026.
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
Cisco disclosed that CVE-2026-20122 (arbitrary file overwrite, CVSS 7.1) and CVE-2026-20128 (information disclosure, CVSS 5.5) affecting Catalyst SD-WAN Manager are under active exploitation. Both require valid credentials. Patches were released in late February, with fixes available in versions 20.9.8.2, 20.12.5.3, 20.15.4.2, and 20.18.2.1. watchTowr observed exploitation from numerous IP addresses, with attackers deploying web shells. The largest spike in activity occurred on March 4. This follows last week's disclosure of CVE-2026-20127 (CVSS 10.0) being exploited by UAT-8616 for persistent footholds in high-value organizations.
Cisco Secure Firewall Management Center - Two Max-Severity Vulnerabilities
Cisco disclosed CVE-2026-20079 (authentication bypass + script execution) and CVE-2026-20131 (Java deserialization RCE), both with CVSS 10.0 scores affecting Secure Firewall Management Center. Both allow unauthenticated remote attackers to execute arbitrary code as root. Disclosed as part of Cisco's biannual update covering 48 vulnerabilities across security products. No active exploitation reported at publication.
12 claims tracked across 4 groups in the last 48 hours. These are unverified claims from ransomware leak sites.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Coinbase Cartel | JBS Brazil | Food Production | Brazil |
| Killsec3 | MyFair | Unknown | Unknown |
| Killsec3 | MedicalGPT | Healthcare Tech | Unknown |
| Killsec3 | yurdriversnetwork | Transportation | Unknown |
| Brain Cipher | liteline.com | Technology | Unknown |
| Pear | INTERACT TECHNOLOGY SOLUTIONS | Technology | USA |
| Pear | CTI & Coordinators | Freight/Logistics | USA/Canada |
| Pear | Skibiel Law | Legal Services | USA |
| Pear | J.R. Martin & Associates | Accounting | USA |
| Pear | Rocky Mountain Associated Physicians | Healthcare | USA |
| Pear | San Diego Eye Bank | Healthcare | USA |
| Crypto24 | Rowad Modern Engineering | Engineering | Unknown |
Phobos ransomware leader pleads guilty, faces up to 20 years in prison
Russian national Evgenii Ptitsyn, 43, pleaded guilty to running the Phobos ransomware operation that extorted more than $39 million from over 1,000 victims globally. Ptitsyn led the group from January 2022 until his May 2024 arrest in South Korea. He was extradited to the US in November 2025. Phobos operated as ransomware-as-a-service, charging affiliates $300 per decryption key and taking a 25% cut. Victims paid $30 million in ransoms, with an additional $9.3 million in losses. US victims included government contractors for DoD and DOE, healthcare facilities, and educational institutions. One educational institution reported losses exceeding $4 million. Ptitsyn agreed to forfeit $1.77 million and pay at least $39.3 million in restitution.
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Broadcom Symantec discovered Iranian state-sponsored group MuddyWater (Seedworm, MOIS-affiliated) targeting U.S. banks, airports, nonprofits, and an Israeli-based software company serving defense and aerospace industries. Attacks began in early February 2026, following U.S. and Israeli military strikes on Iran. The campaign deploys Dindoor, a new backdoor using the Deno JavaScript runtime, and Fakeset, a Python backdoor. Attackers attempted data exfiltration using Rclone to Wasabi cloud storage. Digital certificates signing Fakeset match those used for Stagecomp and Darkcomp malware, confirming MuddyWater attribution. MuddyWater has also been observed scanning for vulnerable Hikvision cameras (CVE-2017-7921, CVE-2023-6895) and exploiting CVE-2021-36260, CVE-2025-34067, CVE-2021-33044 for camera compromise, potentially for battle damage assessment ahead of kinetic operations.
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
Microsoft Threat Intelligence identified a new ClickFix variant targeting Windows Terminal (Win+X then I) instead of the Run dialog. The campaign surfaced in February and tricks users into pasting encoded PowerShell commands framed as verification or troubleshooting steps. Windows Terminal is a legitimate admin tool that blends into routine system activity, evading detection. The payload deploys Lumma Stealer, which injects into Chrome and Edge to harvest credentials. One infection chain downloads 7-Zip and an encrypted archive, establishes persistence, modifies Defender exclusions, and collects browser data. A second variant uses EtherHiding (blockchain-based payload hosting) before deploying the credential harvester.
CL-UNK-1068: Years of Undetected Operations Targeting High-Value Sectors
Palo Alto Unit 42 documented CL-UNK-1068, a Chinese threat actor conducting cyberespionage since at least 2020 targeting aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications sectors across South, Southeast, and East Asia. The group uses GodZilla and AntSword web shells written in English/Simplified Chinese, deploys custom malware and modified open-source tools (Fast Reverse Proxy, Xnote), and leverages Python executables for DLL side-loading. Attackers steal web.config, .aspx, .asmx, .asax, and .dll files from IIS web servers for credential harvesting and vulnerability discovery.
Son of government contractor arrested after alleged $46M crypto heist from US Marshals
John Daghita was arrested in Saint Martin after allegedly stealing more than $46 million in seized cryptocurrency from the US Marshals Service. Daghita is the son of Dean Daghita, who heads Command Services & Support (CMDSS), which holds a $4 million mission-critical contract for seized asset management with the US Marshals. Blockchain investigator ZachXBT traced the theft to wallet addresses controlled by Daghita, linking the funds to a 2024 theft of cryptocurrency seized after the 2016 Bitfinex hack. The case surfaced after Daghita engaged in a public Telegram spat over cryptocurrency holdings, allowing investigators to identify wallet transactions.
Ghanaian man pleads guilty to role in $100 million fraud ring
Derrick Van Yeboah, 40, pleaded guilty to conspiracy to commit wire fraud for his role in a Ghana-based fraud operation that stole over $100 million from U.S. victims through BEC attacks and romance scams. The operation ran from 2016 to May 2023 and targeted vulnerable older Americans living alone. Van Yeboah personally conducted many romance scams, linked to more than $10 million in losses. He agreed to pay over $10 million in restitution and faces up to 20 years in prison. Three other members were extradited to the U.S. in August 2025.
Google says 90 zero-days were exploited in attacks last year
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, up 15% from 2024 (78) but below the 2023 record (100). 47 targeted end-user platforms, 43 targeted enterprise products (security appliances, networking infrastructure, VPNs, virtualization platforms). This marks both the highest raw number and proportion of enterprise zero-days on record. Memory safety issues accounted for 35% of exploited zero-days. Operating systems were the most exploited category (24 desktop OS, 15 mobile), while browser zero-days dropped to eight. Microsoft was the top targeted vendor (25), followed by Google (11), Apple (8), Cisco (4), Fortinet (4), Ivanti (3), and VMware (3). Commercial spyware vendors surpassed state-sponsored groups as the largest users of zero-days for the first time. China-linked espionage groups exploited 10 zero-days, primarily targeting edge devices and security appliances. Financially motivated actors (ransomware, data extortion) exploited nine zero-days.
2026 Browser Data Reveals Major Enterprise Security Blind Spots
Keep Aware's 2026 State of Browser Security Report shows 41% of end users interacted with at least one AI web tool, averaging 1.91 AI tools per person. Employees paste and upload internal documents, source code, financial data, and regulated content into AI systems, often outside security controls. During a one-month snapshot, 54% of sensitive inputs to web apps went to corporate accounts, while 46% went to personal accounts or unverified work accounts. Sensitive uploads concentrated in SharePoint, Google services, Slack, and Box, but accessed under personal identities outside enterprise governance. Traditional DLP solutions built around email gateways and endpoint monitoring cannot inspect typed inputs, pasted data, or file uploads occurring directly in browser sessions.
Where Multi-Factor Authentication Stops and Credential Abuse Starts
Organizations deploy MFA through identity providers like Entra ID, Okta, or Google Workspace and assume credential theft is mitigated. In Windows environments this assumption breaks down because many authentication paths rely solely on Active Directory and never trigger MFA prompts. Interactive Windows logon to domain-joined machines validates through on-prem domain controllers via Kerberos or NTLM, bypassing cloud MFA policies. Direct RDP access doesn't automatically pass through cloud-based MFA controls. NTLM authentication supports pass-the-hash attacks where MFA provides no protection. Kerberos ticket abuse (pass-the-ticket, Golden Ticket, Silver Ticket) enables lateral movement without triggering MFA. Local administrator accounts with reused passwords bypass MFA entirely.
Microsoft kicks new Outlook opt-out deadline down the road to 2027
Microsoft delayed the opt-out phase for new Outlook from April 2026 to March 2027, giving administrators 12 more months to prepare for migration. The delay acknowledges that new Outlook still lacks key features many enterprises need, particularly limited support for Outlook Data Files (.pst). Administrators will have at least 12 months of notice before the cutover stage (no switching back to classic Outlook). Existing classic Outlook installations will be supported until at least 2029.
Microsoft finally fixes Windows 10 Recovery Environment after breaking it in October
Microsoft released KB5068164 to fix a Windows Recovery Environment (WinRE) bug introduced in the October 14, 2025 update on Windows 10's end-of-support date. The bug prevented WinRE from launching on affected devices. The fix covers Windows 10 21H2 and 22H2. Microsoft broke the recovery environment on end-of-life day and took five months to release a fix.
Chrome Moves to Two-Week Release Cycle
Google announced Chrome will move from a four-week to a two-week release cycle to deliver performance improvements, fixes, and new capabilities faster. The change applies to major Chrome versions and beta releases. Google has been shipping Chrome every four weeks since 2021 and security updates weekly since 2023.
Phishing Campaign Deploys Multiple Malware Strains
Ukraine's CERT-UA warned of phishing emails targeting Ukrainian government institutions with ZIP archives (or links to XSS-vulnerable websites) distributing SHADOWSNIFF and SALATSTEALER infostealers and DEAFTICKK backdoor. The campaign is attributed to UAC-0252. A separate suspected Russian espionage campaign is targeting Ukraine with BadPaw and MeowMeow malware, likely linked to APT28.
Fake RMM Service Spreads RAT via Phishing
A new malware-as-a-service called TrustConnect masqueraded as a legitimate remote monitoring and management tool for $300 per month. Multiple threat actors distributed the malware via phishing emails as event invites or bid proposals. The RAT backdoors machines and gives full mouse and keyboard control, allowing screen recording and streaming. Some campaigns also delivered legitimate RMM tools (ScreenConnect, LogMeIn Resolve) alongside TrustConnect. After Proofpoint disrupted infrastructure on February 17, the threat actor rebranded as DocConnect. The campaigns show overlap with techniques used in RMM abuse and are linked to RedLine Stealer users.
Delta Electronics CNCSoft-G2 (CVE-2026-3094)
Delta Electronics CNCSoft-G2 devices prior to version V2.1.0.39 are vulnerable to an out-of-bounds write while parsing DPAX files in the DOPSoft component. Successful exploitation could result in remote code execution.
Microsoft CVE Disclosures
Microsoft published several CVEs in the MSRC Security Update Guide with limited details: - CVE-2026-21536: Microsoft Devices Pricing Program RCE - CVE-2026-23651: Microsoft ACI Confidential Containers elevation of privilege (permissive regex in Azure Compute Gallery) - CVE-2026-26125: Payment Orchestrator Service elevation of privilege - CVE-2026-27141: HTTP/2 frame handling can cause server panic in golang.org/x/net - CVE-2026-24821: Heap-based buffer over-read in turanszkij/WickedEngine Lua code compilation - CVE-2025-68121: Unexpected session resumption in crypto/tls - CVE-2024-53219: virtiofs kernel direct IO vulnerability
Details are minimal. Monitor for patches in upcoming Patch Tuesday releases.
This week's themes: Active exploitation of enterprise edge infrastructure dominates the threat landscape. Cisco's SD-WAN and firewall vulnerabilities, along with CISA's KEV additions (Hikvision, Rockwell), reinforce that edge devices and security appliances are prime targets for initial access and persistence. Google's zero-day report confirms 2025 was the first year commercial spyware vendors outpaced state-sponsored groups in zero-day usage, while enterprise tech accounted for 48% of all exploited zero-days. Iran-linked MuddyWater's campaign targeting U.S. banks and defense contractors shows state actors continue to exploit camera and edge device vulnerabilities for operational support. The Phobos ransomware guilty plea and ongoing ransomware claims against healthcare and legal sectors underscore the persistence of financially motivated threats.